In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://ionic.io/docs/identity-vault/changelog | release notes vendor advisory |
http://seclists.org/fulldisclosure/2021/Nov/41 | mailing list third party advisory exploit |
http://packetstormsecurity.com/files/165027/Ionic-Identity-Vault-5.0.4-PIN-Unlock-Lockout-Bypass.html | third party advisory |